CVE-2023-42791Relative Path Traversal in Fortinet Fortimanager

Severity
8.8HIGHNVD
EPSS
14.1%
top 5.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 20

Description

A relative path traversal in Fortinet FortiManager version 7.4.0 and 7.2.0 through 7.2.3 and 7.0.0 through 7.0.8 and 6.4.0 through 6.4.12 and 6.2.0 through 6.2.11 allows attacker to execute unauthorized code or commands via crafted HTTP requests.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

NVDfortinet/fortimanager6.2.06.2.12+4
CVEListV5fortinet/fortimanager7.2.07.2.3+4
CVEListV5fortinet/fortianalyzer7.2.07.2.3+4

🔴Vulnerability Details

2
CVEList
CVE-2023-42791: A relative path traversal in Fortinet FortiManager version 72024-02-20
GHSA
GHSA-c2qq-2j48-5pr5: A relative path traversal in Fortinet FortiManager version 72024-02-20

📋Vendor Advisories

1
Fortinet
Path traversal via unrestricted file upload2024-02-20
CVE-2023-42791 — Relative Path Traversal in Fortinet | cvebase